PT-2016-1643 · Rockwell Automation · Integrated Architecture Builder

Ivan Sanchez

·

Publicado

2016-04-06

·

Atualizado

2016-04-07

·

CVE-2016-2277

CVSS v2.0

6.9

Média

VetorAV:L/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Rockwell Automation Integrated Architecture Builder (IAB) versions prior to 9.6.0.8 Rockwell Automation Integrated Architecture Builder (IAB) versions 9.7.x prior to 9.7.0.2
Description The issue is related to insufficient access control in the IAB.exe component, allowing remote attackers to execute arbitrary code via a crafted project file. This can be exploited by an attacker to gain unauthorized access and execute malicious code.
Recommendations For versions prior to 9.6.0.8, update to version 9.6.0.8 or later. For versions 9.7.x prior to 9.7.0.2, update to version 9.7.0.2 or later.

Correção

Improper Access Control

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2016-00955
CVE-2016-2277

Produtos afetados

Integrated Architecture Builder